Features AI Assistant Pricing Compare Docs Download →
HIPAA Compliant Last audited Apr 2026 · BAA available

A phone system healthcare
practices can trust

Bukkii Phone is built and operated to meet the standards of the Health Insurance Portability and Accountability Act (HIPAA). Every call, message, and AI interaction handling Protected Health Information (PHI) is encrypted, logged, and protected — backed by a signed Business Associate Agreement (BAA).

AES-256 Encryption at rest
TLS 1.3 Encryption in transit
BAA Signed Business Associate
24/7 Audit logging
What we protect

Every form of PHI on our platform

Bukkii Phone treats voice, text, and AI-generated data with the same protections required for medical records.

Voice recordings & transcripts

Encrypted with AES-256 at rest and accessible only to authorized staff. Auto-deleted after retention window expires.

SMS & voicemail content

Two-way SMS and AI-summarized voicemails are encrypted end-to-end. PHI is masked in our internal systems and admin tools.

Caller identifiers & metadata

Phone numbers, timestamps, call duration, and AI conversation logs all treated as PHI. Logged to a tamper-evident audit trail.

AI-generated content

Our AI Assistant runs in HIPAA-eligible regions. PHI never leaves the BAA-covered infrastructure — no third-party LLM exposure.

Patient appointment data

Booking records, calendar syncs, and reminder messages are scoped per practice. Cross-tenant data isolation is enforced at the database level.

Backups & archives

Backups are encrypted with separate keys, geo-redundant within the United States, and deleted on customer request within 30 days.

Security architecture

Defense in depth — the same controls used by enterprise health systems

1

Identity & Access

SSO via Okta / Google Workspace, mandatory 2FA for admins, role-based access controls (RBAC).

2

Encryption

AES-256 at rest (AWS KMS managed keys) and TLS 1.3 for all data in transit. Customer-managed keys (CMK) available on Enterprise.

3

Network isolation

PHI processed inside private VPCs with no direct internet exposure. Egress monitored and restricted to approved endpoints.

4

Audit logs

Every access to PHI logged with user, IP, timestamp. Retained 6 years per HIPAA §164.316(b)(2)(i). Customer-exportable.

5

Breach response

Incident response plan tested quarterly. Notification within 60 days of discovery, per HIPAA Breach Notification Rule.

99.99%
Uptime SLA
< 60d
Breach notification
6 yrs
Audit log retention
100%
U.S. data residency

All PHI stored and processed exclusively in U.S.-based AWS regions (us-east-1 & us-west-2). No data transfers outside HIPAA-eligible infrastructure.

Business Associate Agreement

A BAA is required by HIPAA whenever a vendor (Business Associate) handles PHI on behalf of a covered entity. We sign BAAs at no extra cost on Pro and Business plans, and provide a standard template within one business day of request.

Request a BAA →
  • Standard template — based on AHIMA model BAA, ready to e-sign.
  • Mutual indemnification — Bukkii accepts liability for breaches caused by our systems.
  • Subcontractor list — Twilio, AWS, OpenAI (only via Azure HIPAA-eligible) — all under their own BAAs.
  • Termination & data return — full PHI export within 14 days of contract end, then permanent deletion.
  • Custom redlines welcome — our compliance team reviews edits within 3 business days.
Built for healthcare

Trusted by practices across the care spectrum

From solo practitioners to multi-location groups, Bukkii Phone supports the full range of healthcare and wellness providers handling PHI.

🦷

Dental practices

DSOs, solo dentists, orthodontics

💆

Med spas & aesthetics

Botox, laser, IV therapy clinics

🩺

Primary care

Family medicine, urgent care

🧠

Mental health

Therapy, counseling, psychiatry

👁️

Vision & optometry

Eye exams, contact lens, LASIK

💉

Specialty clinics

Dermatology, chiropractic, physical therapy

🏥

Outpatient surgery

ASCs, plastic surgery, podiatry

💊

Pharmacy & compounding

Independent & specialty pharmacies

Beyond HIPAA

Independent verification & certifications

HIPAA is the floor — we operate to higher security frameworks audited by independent third parties.

HIPAA

Privacy, Security & Breach Notification Rules

SOC 2 Type II

Annual audit (security, availability, confidentiality)

ISO 27001

In progress · expected Q4 2026

PCI DSS

For payment processing (via Stripe)

FAQ

Common compliance questions

Yes — if you are a Covered Entity (or another BA) that will transmit PHI through our system. Email [email protected] with your practice name and we will send a counter-signed BAA within one business day. You can begin using non-PHI features immediately while the BAA is in flight.
All PHI is stored in U.S.-based AWS regions (us-east-1 and us-west-2). We do not transfer PHI to non-HIPAA-eligible regions, third-party processors, or international data centers.
No. Our AI runs through HIPAA-eligible deployments only — primarily Azure OpenAI Service (HIPAA-covered) and on-premise inference. We have signed BAAs with all model providers in our supply chain. Raw audio and transcripts never leave covered infrastructure.
Per HIPAA Breach Notification Rule (45 CFR §§164.400-414), affected covered entities are notified without unreasonable delay — within 60 days of discovery. Our incident response plan is tested quarterly and includes forensic analysis, scope determination, and direct customer communication via your designated security contact.
Yes. Full PHI export is available anytime via dashboard (CSV + JSON for messages, MP3 for recordings). On contract termination we provide a final export within 14 days, then permanently delete all PHI within 30 days — including encrypted backups. Deletion certificates available on request.
Access is restricted to the minimum necessary, per HIPAA §164.502(b). Customer success and engineering staff cannot view PHI by default — access requires a documented support ticket from your team and is logged to a tamper-evident audit trail. All staff complete annual HIPAA training and sign individual confidentiality agreements.
Our active subprocessors handling PHI: AWS (compute & storage), Twilio (telephony), Azure OpenAI (AI), Stripe (billing — non-PHI). All subprocessors operate under their own BAAs. Updated list at /subprocessors with 30 days advance notice of changes.
This page summarizes Bukkii Phone's HIPAA program in plain language. It is not a substitute for the executed Business Associate Agreement, which governs the legal relationship. For specific compliance questions or to request our security whitepaper, contact [email protected].

Ready to bring HIPAA-compliant calling to your practice?

14-day free trial · BAA on request · No setup fee · Cancel anytime